component-validator

Fail

Audited by Snyk on Jun 12, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.80). The sub-agent is instructed to Read the full component JSON and include "Evidence — short quote" for findings, so if that JSON contains secrets (API keys, passwords, connection strings) the LLM may be required to reproduce them verbatim in its punch-list output; the prompt gives no redaction guidance.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 12, 2026, 09:16 PM
Issues
1
Security Audit — snyk — component-validator